Splunk Search

Splunk Search
Community Activity
prettysunshinez
All, I'm able to extract the second word but now the requirement is little different. _time _raw Shivera 346.789.6...
by prettysunshinez Explorer in Splunk Search 12-23-2019
0 2
0
2
SoknySplunk
Hi , In splunk query i need to convert time format as below . Current format - 08:09.23 AM, Fri 06/10/2016 Require...
by SoknySplunk Loves-to-Learn Lots in Splunk Search 12-23-2019
0 1
0
1
jtpryan
I have a number of Jenkins jobs for which I would like to create a dashboard with search (pull downs, form fills). Th...
by jtpryan New Member in Splunk Search 12-22-2019
0 1
0
1
jyothishtj
Hi All, I am new to splunk. I got a transaction which is flowing through multiple applications. I got a requirement ...
by jyothishtj New Member in Splunk Search 12-22-2019
0 7
0
7
prettysunshinez
All, I have a question on how to perform a search with the strings that are not available in lookup file.. I have a...
by prettysunshinez Explorer in Splunk Search 12-22-2019
0 1
0
1
darrenfuller
Hi Regexian Splunkers, I have an event that looks like so: 2020-02-20 20:22:02.202020 test:>"value" test1:>"value...
by darrenfuller Contributor in Splunk Search 12-22-2019
0 1
0
1
jwalzerpitt
I am using the Splunk 30 day usage search and would like to add the 30 day average into the search and then as on ove...
by jwalzerpitt Influencer in Splunk Search 12-21-2019
0 1
0
1
jaihind_nalla
Hi, i have log file and i am using startswith Starting Dispatcher and endswith completed. but some times in the log t...
by jaihind_nalla New Member in Splunk Search 12-21-2019
0 2
0
2
trojan_81
All, I want search a subnet over all indexes and sourcetypes. The subnet is 5.5.0.0/16 How would the query look so I...
by trojan_81 Path Finder in Splunk Search 12-21-2019
0 5
0
5
pgadhari
I am getting subsearch error while using the join command in my search. I have to use join command to connect 2 sourc...
by pgadhari Builder in Splunk Search 12-21-2019
0 9
0
9
richardphung
I have the following search: index="*" sourcetype=endpoints [search index="*" signature="sig_id" | dedup dest | fiel...
by richardphung Communicator in Splunk Search 12-21-2019
0 6
0
6
infosecnav
We upgraded our indexers from 6.6.4 to 7.3.3 and now any search gives us: [sptsp005] Could not load lookup=LOOKUP-si...
by infosecnav Engager in Splunk Search 12-21-2019
1 1
1
1
ocnarb
Example: _time---value---group 00:01------2---------2 00:02------3---------5 00:03------4---------9 00:04------2----...
by ocnarb New Member in Splunk Search 12-20-2019
0 4
0
4
rczone
Im creating link to different dashboards based on the application clicked on from the main form So i have a variab...
by rczone Path Finder in Splunk Search 12-20-2019
1 1
1
1
psychogyiokosta
I index manually through UI the log file i wish to index (Data Inputs > Add new > Index Once) and select all the conf...
by psychogyiokosta New Member in Splunk Search 12-20-2019
0 7
0
7
johann2017
Hello there. I want to build a query that alerts off when a single source IP or source computer is attempting to logo...
by johann2017 Explorer in Splunk Search 12-20-2019
0 6
0
6
pacifikn
Greetings!! I would like to ask a question about dedup eg: |dedup host ,IP |dedup host |dedup IP I've tried ...
by pacifikn Communicator in Splunk Search 12-20-2019
0 5
0
5
migullmills
I am using the following query to show the duration of a accounts logon and logoff. The results come back in epoch ti...
by migullmills Explorer in Splunk Search 12-20-2019
1 2
1
2
raghav4a1
i need to store a numerical value in Energ1 and store a string value in energy1 and use them in the last search ...
by raghav4a1 New Member in Splunk Search 12-20-2019
0 1
0
1
nilbak1
Can anyone help me to understand below condition where _time>=if("$field1.earliest$"=="0",1,relative_time(now(),"$f...
by nilbak1 Communicator in Splunk Search 12-20-2019
0 1
0
1
egur
Hi, I'm trying to fill empty hours (without events) using makecontinuous. The time column created in the query/ | t...
by egur New Member in Splunk Search 12-19-2019
0 2
0
2
MichaelPriest
I'd like to extend the width of my drop down box in my dashboard because the source names are quite long and i'd like...
by MichaelPriest Communicator in Splunk Search 12-19-2019
2 9
2
9
bcarr12
Hi all, I am working with a log that can sometimes have the same field in one log entry more than one time, but with...
by bcarr12 Path Finder in Splunk Search 12-19-2019
0 5
0
5
rafadvega
I had the next events examples: 2019-09-16T13:27:10.169107+02:00 koopa.browser.local node= koopa.browser.local type...
by rafadvega Path Finder in Splunk Search 12-19-2019
1 3
1
3
bmorgenthaler
Okay I'm pulling my hair out here. I'm playing around with Windows Defender Events, trying to capture them and get th...
by bmorgenthaler Path Finder in Splunk Search 12-19-2019
0 4
0
4
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors